Logo
Galaxy Logo

Contact Us

B Wing, 602, Lotus Corporate Park, Graham Firth Compound, Off. Western Express Highway, Goregaon East, Mumbai – 400063, India

+91-22-46108777

marketing@goapl.com

Follow Us

What We Solve

  • Modernising Legacy Applications
  • Securing the Hybrid Enterprise
  • Scaling Without Complexity
  • Reducing IT Operational Costs
  • Building Cloud-Native Capabilities
  • Positive Business Outcomes using AI

How We Work

  • Our Engagement Model
  • Managed Services Model
  • SLA & Accountability Standards

Our Expertise

  • Data Center Architecture
  • Cybersecurity & Zero Trust
  • Cloud & Multi-Cloud Strategy
  • Enterprise Networking
  • AI-Ready Infrastructure
  • Artificial Intelligence & Machine Learning
  • End-User Experience

Products

  • Auxhealium
  • Protaigo

Insights

  • Events
  • The Galaxy Blog
  • Case Studies
  • Executive Briefings
  • Newsletters

About

  • Our Story & 38 Years of Expertise
  • Leadership & Advisory Board
  • Awards & Recognition
  • Careers
  • ESG & Responsibility
  • CSR

Talk to Us

  • Schedule a Briefing
  • Request an Assessment
  • Support
©Galaxy Office Automation Pvt. Ltd. 2026
Privacy PolicyDisclaimerTerms of Service
HomeCareersSenior Application Security / Product Security Engineer

Senior Application Security / Product Security Engineer

Cybersecurity & Networking PracticeMumbaiFull Time7+ years
Apply for This Role← All Openings

Role Summary

We are seeking an experienced Application Security / Product Security Engineer to help secure our applications and products throughout the software development lifecycle. The ideal candidate will have strong knowledge of cloud-based architectures, application security best practices, and secure SDLC, along with hands-on experience performing security design reviews and application testing across web, API, mobile, and thick client applications. This role requires close collaboration with engineering, architecture, DevOps, and product teams to identify security risks early and ensure secure product development.

Key Responsibilities

  • Integrate security practices into the Software Development Lifecycle (SDLC).
  • Perform application security design reviews for new and existing products.
  • Conduct manual and automated security testing of:
  • Identify vulnerabilities such as OWASP Top 10, authentication issues, authorization flaws, and API security risks.
  • Review cloud architecture and deployments (AWS, Azure, GCP) for security best practices.
  • Work with development teams to prioritize and remediate vulnerabilities.
  • Perform threat modeling and security architecture assessments.
  • Track vulnerabilities, remediation status, and risk metrics using Excel or vulnerability management tools.

Required Skills & Qualifications

  • Strong understanding of Application Security and Product Security principles.
  • Experience with secure SDLC practices.
  • Knowledge of cloud platforms (AWS / Azure / GCP) and cloud security architecture.
  • Experience performing security design reviews and threat modeling.
  • Familiarity with OWASP Top 10, API Security Top 10, and common vulnerability classes.
  • Experience using security tools such as: SAST, DAST, SCA, API testing tools

Preferred Background

  • Certifications such as: CEH, OSCP, GWAPT, CSSLP, CISSP
  • Experience with DevSecOps pipelines and CI/CD security integration and architecture design principles.
  • Experience with container and Kubernetes security and cloud security. Soft Skills
  • Strong communication and collaboration skills
  • Ability to manage multiple projects and stakeholders
  • Analytical thinking and problem-solving ability

Galaxy Office Automation is an equal-opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration without regard to race, religion, gender, age, or disability status.

Ready to join?

Apply for this position

Not the right role?

We keep CVs on file for future openings that match your profile.

Send us your CV anyway